Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the…
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the…
A malicious RubyGems campaign has turned seemingly useful developer packages into tools for hidden cryptocurrency mining. The poisoned packages can consume a machine’s computing power,…
Attackers are increasingly abusing Microsoft Teams to impersonate internal IT support and trick employees into handing over remote access and corporate credentials, even as traditional…
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage…
Swati KhandelwalJul 23, 2026Malware / Threat Intelligence An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has…
Strip away the geopolitics, the hacktivist noise, and the espionage headlines, and one number from the first half of 2026 stands out above everything else:…
Google has launched a new selfie video sign-in feature, allowing users another option to log in to their accounts or recover them in case they…
US fast-food chain Chick-fil-A has disclosed a data breach stemming from a credential stuffing attack targeting its customers’ online accounts. According to notifications sent to…
A morass of rules is forcing companies to report the same information multiple times — and sometimes, those rules conflict. Source link
A ‘planted accomplice’ that does all the work Once activated, AgentForger can perform reconnaissance to create an internal map of a company. For instance, agents…
During routine monitoring, the Wiz Research Team observed an exploitation attempt targeting one of our honeypot servers running TeamCity, a popular CI/CD tool. Our investigation…
Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers’ personally identifiable information (PII). The company has…